2025 CVE Vulnerabilities
45,203 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-65012 | MEDIUM | 5.4 | 0.2% | Nov 18, 2025 | Kirby is an open-source content management system. From versions 5.0.0 to 5.1.3, attackers could change the title of any... |
| CVE-2025-64515 | MEDIUM | 4.3 | 0.2% | Nov 18, 2025 | Open Forms allows users create and publish smart forms. Prior to versions 3.2.7 and 3.3.3, forms where the prefill data ... |
| CVE-2025-64325 | CRITICAL | 9 | 0.4% | Nov 18, 2025 | Emby Server is a personal media server. Prior to version 4.8.1.0 and prior to Beta version 4.9.0.0-beta, a malicious use... |
| CVE-2025-64324 | HIGH | 7.7 | 0.2% | Nov 18, 2025 | KubeVirt is a virtual machine management add-on for Kubernetes. The `hostDisk` feature in KubeVirt allows mounting a hos... |
| CVE-2025-62406 | HIGH | 8.8 | 0.3% | Nov 18, 2025 | Piwigo is a full featured open source photo gallery application for the web. In Piwigo 15.6.0, using the password reset ... |
| CVE-2025-54990 | MEDIUM | 5.3 | 0.2% | Nov 18, 2025 | XWiki AdminTools integrates administrative tools for managing a running XWiki instance. Prior to version 1.1, users with... |
| CVE-2025-63229 | MEDIUM | 5.4 | 0.2% | Nov 18, 2025 | The Mozart FM Transmitter web management interface on version WEBMOZZI-00287, contains a reflected Cross-Site Scripting ... |
| CVE-2025-63217 | CRITICAL | 9.8 | 0.5% | Nov 18, 2025 | The Itel DAB MUX (IDMUX build c041640a) is vulnerable to Authentication Bypass due to improper JWT validation across dev... |
| CVE-2025-63216 | CRITICAL | 10 | 0.7% | Nov 18, 2025 | The Itel DAB Gateway (IDGat build c041640a) is vulnerable to Authentication Bypass due to improper JWT validation across... |
| CVE-2025-63215 | HIGH | 7.2 | 0.4% | Nov 18, 2025 | The Sound4 IMPACT web-based management interface is vulnerable to Remote Code Execution (RCE) via a malicious firmware u... |
| CVE-2025-12119 | LOW | 3.3 | 0.2% | Nov 18, 2025 | A mongoc_bulk_operation_t may read invalid memory if large options are passed. |
| CVE-2025-63228 | CRITICAL | 9.8 | 0.7% | Nov 18, 2025 | The Mozart FM Transmitter web management interface on version WEBMOZZI-00287, contains an unauthenticated file upload vu... |
| CVE-2025-63227 | HIGH | 7.2 | 0.5% | Nov 18, 2025 | The Mozart FM Transmitter web management interface on version WEBMOZZI-00287, contains an unrestricted file upload vulne... |
| CVE-2025-63226 | MEDIUM | 5.7 | 0.2% | Nov 18, 2025 | The Sencore SMP100 SMP Media Platform (firmware versions V4.2.160, V60.1.4, V60.1.29) is vulnerable to session hijacking... |
| CVE-2025-37162 | HIGH | 8.8 | 0.8% | Nov 18, 2025 | A vulnerability in the command line interface of affected devices could allow an authenticated remote attacker to conduc... |
| CVE-2025-37161 | HIGH | 7.5 | 0.3% | Nov 18, 2025 | A vulnerability in the web-based management interface of affected products could allow an unauthenticated remote attacke... |
| CVE-2025-63955 | HIGH | 7.5 | 0.2% | Nov 18, 2025 | A Cross-Site Request Forgery (CSRF) vulnerability in the manage-students.php component of PHPGurukul Student Record Syst... |
| CVE-2025-63749 | MEDIUM | 6.5 | 0.9% | Nov 18, 2025 | pnetlab 5.3.11 is vulnerable to Command Injection via the qemu_options parameter. |
| CVE-2025-63693 | MEDIUM | 5.4 | 0.2% | Nov 18, 2025 | The comment editing template (dzz/comment/template/edit_form.htm) in DzzOffice 2.3.x lacks adequate security escaping fo... |
| CVE-2025-63225 | CRITICAL | 9.8 | 0.5% | Nov 18, 2025 | The Eurolab ELTS100_UBX device (firmware version ELTS100v1.UBX) is vulnerable to Broken Access Control due to missing au... |
| CVE-2025-61664 | MEDIUM | 4.9 | 0.1% | Nov 18, 2025 | A vulnerability in the GRUB2 bootloader has been identified in the normal module. This flaw, a memory Use After Free iss... |
| CVE-2025-61663 | MEDIUM | 4.9 | 0.1% | Nov 18, 2025 | A vulnerability has been identified in the GRUB2 bootloader's normal command that poses an immediate Denial of Service (... |
| CVE-2025-61662 | HIGH | 7.8 | 0.2% | Nov 18, 2025 | A Use-After-Free vulnerability has been discovered in GRUB's gettext module. This flaw stems from a programming error wh... |
| CVE-2025-61661 | MEDIUM | 4.8 | 0.2% | Nov 18, 2025 | A vulnerability has been identified in the GRUB (Grand Unified Bootloader) component. This flaw occurs because the bootl... |
| CVE-2025-60455 | HIGH | 8.4 | 0.3% | Nov 18, 2025 | Unsafe Deserialization vulnerability in Modular Max Serve before 25.6, specifically when the "--experimental-enable-kvca... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now